Perform a sql injection attack in the search for users box

Assignment Help Database Management System
Reference no: EM132135940

SQL injection on a search

The way Search performs its task is by executing the following query (in a php script):

         $var=stripslashes($_POST['search']);
         $query = "SELECT username from lab1_login where username ='".$var."'";

The structure of the database table that is maintained by the webservice and on which this query runs is as follows:

mysql> desc lab1_login;

Field

Type

Null

Key

Default

Extra

uid            

int(11)  

NO

PRI


auto_increment

username

varchar(255)

YES




password

varchar(255)

YES




Your task is to now perform a SQL Injection attack in the "Search for users" box such that it prints out all the usernames and passwords.

Reference no: EM132135940

Questions Cloud

What can you do to identify duplicated data : What can you do to identify duplicated when the patient is being registered and after?
What is the probability that the student answers : If the student randomly guesses on each questions, what is the probability that the student answers fewer than 4 questions correctly?
Produce a report with descriptive report and column headings : Produce a report with descriptive report and column headings. Be sure there is enough data to prove the selection and sort worked as required.
What is the probability that the student answers : If the student randomly guesses on each question , what is the probability that the student answers 3 questions correctly?
Perform a sql injection attack in the search for users box : Your task is to now perform a SQL Injection attack in the "Search for users" box such that it prints out all the usernames and passwords.
What is the set of possible values of variable x : A coin is flipped five times in an experiment. If x is the number of heads that turn out in the experiment, what is the set of possible values of variable x?
What is the df value for the t statistic for study : An independent-measures study has one sample with n = 10 and a second sample with n = 15 to compare two experimental treatments
Dogs weight and how long the dog lived : The following is data a veterinarian collected from some of her clients. it is a rough estimate % of dogs weight and how long the dog lived
Write a pl-sql stored function that takes username : Write a PL/SQL stored function that takes username as input and returns number of documents that user has permissions to view.

Reviews

Write a Review

Database Management System Questions & Answers

  Knowledge and data warehousing

Design a dimensional model for analysing Purchases for Adventure Works Cycles and implement it as cubes using SQL Server Analysis Services. The AdventureWorks OLTP sample database is the data source for you BI analysis.

  Design a database schema

Design a Database schema

  Entity-relationship diagram

Create an entity-relationship diagram and design accompanying table layout using sound relational modeling practices and concepts.

  Implement a database of courses and students for a school

Implement a database of courses and students for a school.

  Prepare the e-r diagram for the movie database

Energy in the home, personal energy use and home energy efficiency and Efficient use of ‘waste' heat and renewable heat sources

  Design relation schemas for the entire database

Design relation schemas for the entire database.

  Prepare the relational schema for database

Prepare the relational schema for database

  Data modeling and normalization

Data Modeling and Normalization

  Use cases perform a requirements analysis for the case study

Use Cases Perform a requirements analysis for the Case Study

  Knowledge and data warehousing

Knowledge and Data Warehousing

  Stack and queue data structure

Identify and explain the differences between a stack and a queue data structure

  Practice on topic of normalization

Practice on topic of Normalization

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd